11–14 May 2008
Hyatt Regency Chicago
US/Central timezone

Vulnerability Scanning and Automated Patching Effort

14 May 2008, 11:00
40m
Columbus E-F (Hyatt Regency Chicago)

Columbus E-F

Hyatt Regency Chicago

151 East Wacker Drive, Chicago, Illinois, USA 60601
Computer Security Tools (unclassified) Wednesday Breakout 3

Speaker

Jon Homer (Idaho National Laboratory)

Description

Vulnerability identification and remediation represents a fine art in the arena of computer security. Discover how the INL has approached scanning, reconciliation, notification, lifecycle tracking, closure, and reporting. We’ll briefly touch on the automation of patching, as well as the resulting impact on business processes and policy. We’ll discuss how we handle non-standard configurations and operating systems, accepted risks, cost vs. risk analysis, and non-cooperative system owners. The close will cover management metrics, requirements and drivers (OMB, PCSP, and Lab Directives), and audits (survival and response).

Primary author

Jon Homer (Idaho National Laboratory)

Presentation materials